
Retrigger Notifications Gravity Forms Security & Risk Analysis
wordpress.org/plugins/retrigger-notifications-gravity-formsResend Gravity Forms entry data to Zapier and Webhook feeds with one click -- no need to resubmit the form.
Is Retrigger Notifications Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Retrigger Notifications Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'retrigger-notifications-gravity-forms' plugin version 1.3 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests. All SQL queries are properly prepared, and there are no known vulnerabilities or CVEs associated with this plugin, indicating a potentially stable and well-maintained codebase in terms of past security issues.
However, significant concerns arise from the static analysis. The plugin exposes a single REST API route that lacks a permission callback, creating an unprotected entry point into the application. While there are no taint flows or direct SQL injection risks identified in this analysis, this unprotected REST API route could still be leveraged for unauthorized actions or information disclosure if it performs sensitive operations. The moderate percentage of properly escaped output also suggests a potential for cross-site scripting (XSS) vulnerabilities, although the absence of critical taint flows mitigates this risk to some extent for now.
In conclusion, while the plugin benefits from a clean vulnerability history and good coding practices in several areas, the unprotected REST API endpoint is a critical oversight that needs immediate attention. Addressing this single, unauthenticated entry point should be the priority, followed by a thorough review of output escaping to ensure full XSS protection.
Key Concerns
- REST API route without permission callback
- Moderate percentage of unescaped output
Retrigger Notifications Gravity Forms Security Vulnerabilities
Retrigger Notifications Gravity Forms Code Analysis
Output Escaping
Retrigger Notifications Gravity Forms Attack Surface
REST API Routes 1
WordPress Hooks 7
Maintenance & Trust
Retrigger Notifications Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Retrigger Notifications Gravity Forms Alternatives
WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress
wp-webhooks
Automate everything & connect your website, plugins and services together with no-code automations. Browse 100+ integrations...
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress
automatorwp
Connect your WordPress plugins, sites & apps together to create automated workflows with the most powerful no-code automator plugin!
Real Time Validation for Gravity Forms
real-time-validation-for-gravity-forms
Real Time Validation for Gravity Forms increases conversion rates of your Gravity Form using inline validation messages as user types in field.
WP-Stateless – Gravity Forms Addon
wp-stateless-gravity-forms-addon
Provides compatibility between the Gravity Forms and the WP-Stateless plugins.
Custom WP Zapier
custom-wp-zapier
Custom WP Zapier is one stop solution for integrating apis to WP.
Retrigger Notifications Gravity Forms Developer Profile
6 plugins · 1K total installs
How We Detect Retrigger Notifications Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/retrigger-notifications-gravity-forms/includes/gf-retrigger-admin.js/wp-content/plugins/retrigger-notifications-gravity-forms/css/gf-retrigger-admin.css/wp-content/plugins/retrigger-notifications-gravity-forms/css/gf-retrigger-frontend.css/wp-content/plugins/retrigger-notifications-gravity-forms/includes/gf-retrigger-admin.jsretrigger-notifications-gravity-forms/css/gf-retrigger-admin.css?ver=retrigger-notifications-gravity-forms/includes/gf-retrigger-admin.js?ver=retrigger-notifications-gravity-forms/css/gf-retrigger-frontend.css?ver=HTML / DOM Fingerprints
gform_notificationsname="zapier_hooks[]"id="zapier_\d+"window.confirmjQuery(document).readywindow.confirm('These entries will be resent to all feeds configured, Are you sure you want to resend the feeds?');/wp-json/gf-retrigger/v1/test-webhook